🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
UY v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing9 sources retrieved model claude-sonnet-5 · 2026-08-05

Uruguay

UY schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, Crypto, AIC

Last updated · 10 categories · 31 claims · 18 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
31Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 30 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Uruguay's data protection authority, the URCDP, has issued Resolution No. 8/2026 on 17 April 2026, recommending the use of model or standard contractual clauses for international data transfers. This is the most recent identified regulatory development in Uruguay's data protection framework and sits inside a domain, cross-border transfer and adequacy, that already carries unusual regional significance: Uruguay is recognised by the European Union as providing an adequate level of data protection, one of a small number of Latin American jurisdictions to hold that status. The new resolution should be read as a reinforcement of, rather than a departure from, that adequacy-conscious posture: rather than introducing new restrictions on outbound transfers, it steers controllers and processors toward standardised contractual mechanisms as good practice for structuring international transfers going forward.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statutory architecture, regulator identity and material/territorial scope are well evidenced by primary EU adequacy documentation and confirmed by IAPP/DataGuidance secondary sources.

Primary frameworkLaw No. 18.331 (LPD) and Decree No. 414/009, as amended by Law No. 19.670 and Decree No. 64/020
Traffic-light rationale — GreenCore statutory architecture, regulator identity and material/territorial scope are well evidenced by primary EU adequacy documentation and confirmed by IAPP/DataGuidance secondary sources.

Sub-modules (5)

Regulator And AuthorityGreen

URCDP is the decentralized supervisory body created to ensure the observance of the constitutionally-inherent right to data protection, operating in association with AGESIC.

Claims (1):

  • The Unidad Reguladora y de Control de Datos Personales (URCDP) is Uruguay's data protection supervisory authority, created as a decentralized body under AGESIC to ensure observance of the right to personal data protection.

Act And InstrumentsGreen

The instrument stack comprises Law 18.331 (2008), Decree 414/009 (2009), amending Law 19.670 (2018), and implementing Decree 64/020 (2020).

Claims (3):

  • Law No. 18.331 on the Protection of Personal Data and Habeas Data Action of 11 August 2008 is Uruguay's foundational data protection statute, largely based on the standards of EU Directive 95/46/EC.
  • Law 18.331 is further complemented by Decree No. 414/009 of 31 August 2009, which lays down the organisation, powers and functioning of the URCDP.
  • Law No. 19.670 of 15 October 2018 amended Law 18.331 to introduce the accountability (responsabilidad proactiva) principle and the DPO figure, later implemented via Decree No. 64/020 of 21 February 2020.

Material ScopeGreen

The LPD covers natural and legal persons' data in public/private databases, carving out personal/household use and public-security/defence/state-security databases.

Claims (1):

  • Law 18.331 governs personal data of both natural and legal persons processed in public- or private-sector databases, excluding data processed for purely personal/household purposes and databases for public security, defence or state security purposes.

Territorial ScopeAmber

Extraterritorial reach is anchored to a 'stable activity' test for controllers/processors under the 2020 implementing decree.

Claims (1):

  • A data controller or processor is deemed established in Uruguay for LPD purposes, including its extraterritorial application, when it carries out a stable activity there.

Regulator Registration And FilingAmber

Uruguay's regime historically requires registration of databases with URCDP as part of its statutory-judicial architecture; granular current filing procedure detail was not independently re-verified against the URCDP portal in this pass.

Claims (1):

  • Uruguay's data protection regime imposes an obligation to register databases with the URCDP as part of its regulatory-judicial system of data protection.
Category narrative123 words

Uruguay's data protection regime is anchored in Law No. 18.331 of 11 August 2008 (the LPD/Habeas Data Act), regulated by Decree No. 414/009 of 31 August 2009, and substantially reformed by Law No. 19.670 of 15 October 2018 (introducing accountability, DPO, breach notification and privacy-by-design/default), with implementing detail added by Decree No. 64/020 of 21 February 2020. The supervisory authority is the Unidad Reguladora y de Control de Datos Personales (URCDP), a decentralized body operating within the orbit of AGESIC. The regime covers personal data of both natural and legal persons processed in public- or private-sector databases, excluding purely personal/household processing and databases serving public security, defence or state-security purposes. Extraterritorial application attaches where a controller/processor carries out a stable activity in Uruguay.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ConfirmedInternational Association of Privacy Professionals — The Unidad Reguladora y de Control de Datos Personales (URCDP) is Uruguay's data protection supervisory authority, created as a decentralized body under AGESIC to ensure observance of the right to personal data protection.observed
  2. ConfirmedOfficial Journal of the European Union — Law No. 18.331 on the Protection of Personal Data and Habeas Data Action of 11 August 2008 is Uruguay's foundational data protection statute, largely based on the standards of EU Directive 95/46/EC.observed
  3. ConfirmedOfficial Journal of the European Union — Law 18.331 is further complemented by Decree No. 414/009 of 31 August 2009, which lays down the organisation, powers and functioning of the URCDP.observed
  4. ConfirmedOneTrust DataGuidance — Law No. 19.670 of 15 October 2018 amended Law 18.331 to introduce the accountability (responsabilidad proactiva) principle and the DPO figure, later implemented via Decree No. 64/020 of 21 February 2020.observed
  5. ConfirmedInternational Association of Privacy Professionals — Law 18.331 governs personal data of both natural and legal persons processed in public- or private-sector databases, excluding data processed for purely personal/household purposes and databases for public security, defence or state security purposes.observed
  6. ProbableInternational Association of Privacy Professionals — A data controller or processor is deemed established in Uruguay for LPD purposes, including its extraterritorial application, when it carries out a stable activity there.observed
  7. ConfirmedInternational Association of Privacy Professionals — Uruguay's data protection regime imposes an obligation to register databases with the URCDP as part of its regulatory-judicial system of data protection.observed

#

Special-category/DPO and anonymisation findings are well sourced; granular lawful-basis and consent-threshold text was not independently retrieved in this pass.

Primary frameworkLaw No. 18.331 (LPD) and Decree No. 414/009, as amended
Traffic-light rationale — AmberSpecial-category/DPO and anonymisation findings are well sourced; granular lawful-basis and consent-threshold text was not independently retrieved in this pass.

Sub-modules (4)

Lawful BasesRed

No enumerated catalogue of lawful bases equivalent to GDPR Art 6 was independently confirmed in this research pass; consent and statutory/contractual necessity are known via secondary literature to underlie the LPD but were not pulled from primary article text.

Absence provenance: unavailable. Searched: Ley 18.331 Uruguay lawful bases article 5 processing grounds.

Special CategoriesAmber

Entities that process sensitive data as their principal business, along with public entities, are subject to enhanced obligations including mandatory DPO designation.

Claims (1):

  • Uruguayan implementing rules require private entities that process sensitive personal data as their main business activity, as well as public entities, to appoint a data protection officer.

Pseudonymisation And AnonymisationGreen

URCDP/AGESIC issued formal guidance distinguishing de-identification, anonymisation, re-identification and pseudonymisation, and Decree 414/009 requires dissociation/pseudonymisation/minimisation techniques in system design.

Claims (2):

  • The URCDP, jointly with AGESIC, issued a de-identification guide in September 2017 defining de-identification, anonymisation, re-identification and pseudonymisation under Uruguayan law.
  • Implementing decree provisions require controllers and processors to incorporate dissociation, pseudonymisation and data-minimisation techniques into database design, processing operations and information systems.
Category narrative80 words

The LPD's 2008 text already incorporated EU-style consent standards, and the 2018/2020 reforms layered on accountability-driven controls around sensitive data and de-identification. Search coverage located strong evidence on DPO thresholds tied to sensitive-data processing and on URCDP/AGESIC anonymisation guidance, but did not surface a fully enumerated lawful-bases catalogue or granular consent-validity thresholds equivalent to GDPR Art 6/7 text for this pass — these remain to be pulled directly from the LPD's Spanish-language articles (arts. 5, 9, 18) for full confidence.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy Professionals — Uruguayan implementing rules require private entities that process sensitive personal data as their main business activity, as well as public entities, to appoint a data protection officer.observed
  2. ConfirmedOneTrust DataGuidance — The URCDP, jointly with AGESIC, issued a de-identification guide in September 2017 defining de-identification, anonymisation, re-identification and pseudonymisation under Uruguayan law.observed
  3. ProbableInternational Association of Privacy Professionals — Implementing decree provisions require controllers and processors to incorporate dissociation, pseudonymisation and data-minimisation techniques into database design, processing operations and information systems.observed

#

Access, rectification/erasure and the Habeas Data enforcement route are well evidenced; portability and precise response-deadline figures are gaps.

Primary frameworkLaw No. 18.331 (LPD)
Traffic-light rationale — AmberAccess, rectification/erasure and the Habeas Data enforcement route are well evidenced; portability and precise response-deadline figures are gaps.

Sub-modules (5)

Access RightGreen

Data subjects may request explicit, unambiguous information on the destination and purpose of their personal data.

Claims (1):

  • Data subjects in Uruguay have the right to access, obtaining explicit and unambiguous information about the destination and purpose of their personal data stored in databases.

Rectification And ErasureGreen

Correction, updating, deletion, inclusion or suppression rights apply where data is erroneous, false, or otherwise no longer fit for purpose.

Claims (1):

  • Data subjects may request correction, updating, deletion, inclusion or suppression of their personal data from public or private databases where the data is erroneous or false.

Restriction And ObjectionRed

No dedicated restriction/objection (including profiling opt-out) provision distinct from rectification/erasure was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Ley 18.331 Uruguay derecho de oposición limitación tratamiento.

Data PortabilityRed

No explicit data-portability right analogous to GDPR Art 20 was located for Uruguay's regime in this research pass.

Absence provenance: unavailable. Searched: Uruguay Ley 18.331 derecho portabilidad de datos.

Deadlines And Response WindowsAmber

The prejudicial-petition/judicial Habeas Data two-step model is confirmed; specific statutory day-count deadlines for controller response were not independently re-verified in this pass.

Claims (1):

  • Uruguayan data subjects are granted a two-step enforcement path: a prejudicial petition directly to the database controller, followed by a judicial Habeas Data action, without prejudice to URCDP's advisory/oversight role.
Category narrative84 words

Uruguay grants a right of access to explicit and unambiguous information on the destination and purpose of stored personal data, plus rights to correction, updating, deletion, inclusion or suppression where data is erroneous or false. Enforcement of these rights follows a two-step model: a prejudicial petition to the controller, followed by a judicial Habeas Data action, without prejudice to URCDP's advisory/oversight role. No explicit, GDPR-Art-20-style portability right was identified for the 2008-era statute in this pass, and statutory response-deadline windows were not independently re-confirmed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy Professionals — Data subjects in Uruguay have the right to access, obtaining explicit and unambiguous information about the destination and purpose of their personal data stored in databases.observed
  2. ConfirmedInternational Association of Privacy Professionals — Data subjects may request correction, updating, deletion, inclusion or suppression of their personal data from public or private databases where the data is erroneous or false.observed
  3. ConfirmedInternational Association of Privacy Professionals — Uruguayan data subjects are granted a two-step enforcement path: a prejudicial petition directly to the database controller, followed by a judicial Habeas Data action, without prejudice to URCDP's advisory/oversight role.observed

#

Accountability, DPO, breach-notification and security-measure obligations are strongly evidenced across multiple secondary sources describing the 2018/2020 decree reforms.

Primary frameworkLaw No. 18.331 (LPD) as amended by Law No. 19.670, implemented via Decree No. 64/020
Traffic-light rationale — GreenAccountability, DPO, breach-notification and security-measure obligations are strongly evidenced across multiple secondary sources describing the 2018/2020 decree reforms.

Sub-modules (7)

Accountability And DpiaGreen

Accountability was formally introduced by the 2018 reform; implementing decree provisions set out DPIA content, triggers, timing and scope.

Claims (2):

  • The accountability (responsabilidad proactiva) principle was introduced into Law 18.331 by the 2018 reform under Law 19.670, requiring controllers and processors to adopt, document, periodically review and evaluate the effectiveness of security and confidentiality measures.
  • Implementing decree provisions set out the content, timing, procedence and scope of the data protection impact assessment obligation.

Dpo RequirementsGreen

DPO appointment must be notified to URCDP within 90 days of processing commencement; the DPO must hold specialised legal knowledge in data protection and observe absolute confidentiality.

Claims (1):

  • Entities designating a DPO must communicate the appointment to the URCDP within 90 days of commencing processing; the DPO must have specialised legal knowledge of data protection and is bound to absolute confidentiality.

Ropa RequirementsRed

No dedicated Records-of-Processing-Activities obligation distinct from general documentation duties was independently confirmed in this pass.

Absence provenance: unavailable. Searched: Uruguay Decreto 64/020 registro de actividades de tratamiento.

Joint Controller ArrangementsAmber

Contractual documentation of third-party data-processing services is required, but a dedicated joint-controller allocation-of-liability regime was not independently confirmed.

Absence provenance: unavailable. Searched: Uruguay Ley 19.670 corresponsables tratamiento conjunto.

Security MeasuresGreen

Proactive-accountability security measures must be documented, periodically reviewed, and evaluated for effectiveness.

Claims (1):

  • Proactive-accountability security measures adopted by controllers and processors must be documented, periodically reviewed, and evaluated for effectiveness.

Breach NotificationGreen

A strict 24-hour impact-minimisation window and 72-hour URCDP notification deadline apply, with no quantitative minimum for triggering the duty; subject notification is required for 'significant' rights impacts.

Claims (2):

  • Upon detecting a security incident affecting personal data, controllers must minimise impacts within the first 24 hours and notify the URCDP within a maximum of 72 hours of becoming aware of the breach, with no minimum quantitative threshold for the notification duty.
  • Data subjects must be notified of a security breach, in clear and simple language, when the breach produces a 'significant' effect on their rights, an undetermined legal concept to be defined by the URCDP in practice.

Retention And DisposalAmber

General retention-period documentation is referenced in decree provisions on system design, but specific statutory retention limits were not independently confirmed in this pass.

Absence provenance: unavailable. Searched: Uruguay Decreto 414/009 plazo conservación de datos.

Category narrative103 words

The 2018 reform (Law 19.670) introduced an accountability/proactive-responsibility principle requiring controllers and processors to adopt, document, periodically review and evaluate the effectiveness of security and confidentiality measures, alongside DPIA obligations. DPO designation must be communicated to URCDP within 90 days of the start of processing, with statutory requirements on legal expertise and confidentiality. Breach notification follows a tight timeline: impact minimisation within 24 hours and URCDP notification within a maximum of 72 hours, with no quantitative minimum threshold, plus subject notification where the breach has a 'significant' effect on rights. Joint-controller arrangements and granular retention/disposal rules were not independently confirmed in this pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedInternational Association of Privacy Professionals — The accountability (responsabilidad proactiva) principle was introduced into Law 18.331 by the 2018 reform under Law 19.670, requiring controllers and processors to adopt, document, periodically review and evaluate the effectiveness of security and confidentiality measures.observed
  2. ProbableInternational Association of Privacy Professionals — Implementing decree provisions set out the content, timing, procedence and scope of the data protection impact assessment obligation.observed
  3. ConfirmedInternational Association of Privacy Professionals — Entities designating a DPO must communicate the appointment to the URCDP within 90 days of commencing processing; the DPO must have specialised legal knowledge of data protection and is bound to absolute confidentiality.observed
  4. ConfirmedInternational Association of Privacy Professionals — Upon detecting a security incident affecting personal data, controllers must minimise impacts within the first 24 hours and notify the URCDP within a maximum of 72 hours of becoming aware of the breach, with no minimum quantitative threshold for the notification duty.observed
  5. ConfirmedInternational Association of Privacy Professionals — Data subjects must be notified of a security breach, in clear and simple language, when the breach produces a 'significant' effect on their rights, an undetermined legal concept to be defined by the URCDP in practice.observed
  6. ConfirmedInternational Association of Privacy Professionals — Proactive-accountability security measures adopted by controllers and processors must be documented, periodically reviewed, and evaluated for effectiveness.observed

#

This module has the deepest, most consistent evidentiary base of the ten, anchored by a primary-source EU Commission decision plus multiple corroborating URCDP resolution descriptions.

Primary frameworkLaw No. 18.331 (LPD) Art. 23, Decree No. 64/020, and URCDP Resolutions 23/2021, 41/2021 and 63/2023
Traffic-light rationale — GreenThis module has the deepest, most consistent evidentiary base of the ten, anchored by a primary-source EU Commission decision plus multiple corroborating URCDP resolution descriptions.

Sub-modules (6)

Transfer MechanismsGreen

Article 23 LPD prohibits transfers to non-adequate destinations absent sufficient guarantees, which may be satisfied via consent, statutory exceptions, or appropriate contractual clauses subject to URCDP acceptance.

Claims (3):

  • Article 23 of Law 18.331 prohibits international transfers of personal data of any kind to countries or international organisations that do not provide adequate levels of protection.
  • The URCDP may authorise a transfer to a non-adequate country where the controller offers sufficient guarantees for the protection of individuals' fundamental rights, which may derive from appropriate contractual clauses.
  • Following the invalidation of the EU-US Privacy Shield and the CJEU's Schrems II ruling, URCDP Resolution No 23/2021 requires that transfers to the United States be justified via data-subject consent or one of the Article 23 exceptions, with URCDP authorisation where applicable.

Adequacy ReceivedGreen

Uruguay received an EU adequacy decision in 2012 under Directive 95/46/EC, still the operative adequacy finding referenced by current practice.

Claims (1):

  • The European Commission adopted Implementing Decision 2012/484/EU on 21 August 2012, recognising Uruguay as ensuring an adequate level of protection for personal data transferred from the EU under Directive 95/46/EC.

Adequacy GrantedGreen

URCDP has issued its own outbound adequacy determinations, most notably the 2021 country list and the 2023 recognition of South Korea and EU-US DPF entities.

Claims (2):

  • URCDP Resolution No 23/2021 of 8 June 2021 established the list of countries considered adequate for international data transfers, based on the Ibero-American Data Protection Standards and the EU GDPR.
  • URCDP Resolution No 63/2023 of 21 November 2023 recognised South Korea and entities certified under the EU-US Data Privacy Framework as providing an adequate level of data protection for cross-border transfers.

Sccs And BcrsAmber

URCDP Resolution 41/2021 provides minimum-content guidance for appropriate contractual clauses used in transfers to non-adequate countries; no distinct BCR framework was confirmed.

Claims (1):

  • URCDP Resolution No 41/2021 of 8 September 2021 provides guidance on the minimum recommended content of appropriate contractual clauses for international transfers of personal data to non-adequate countries.

Transfer Impact AssessmentGreen

Decree 64/020 Article 6 requires an impact assessment prior to transferring data to states/organisations lacking an adequate protection level.

Claims (1):

  • Article 6 of Decree No. 64/2020 requires controllers to carry out an impact assessment before transferring data to states or organisations lacking an adequate level of data protection.

Data LocalisationRed

No mandatory data-localisation regime (partial or absolute) was identified for Uruguay in this research pass.

Absence provenance: unavailable. Searched: Uruguay data localisation requirement personal data servers, Uruguay localización de datos ley.

Category narrative111 words

Uruguay is the only Latin American jurisdiction to hold an EU adequacy decision (Commission Implementing Decision 2012/484/EU, under the former Directive 95/46/EC framework, still in effect). Domestically, Article 23 of the LPD prohibits transfers to non-adequate countries/organisations absent sufficient guarantees, which the URCDP may accept in the form of appropriate contractual clauses; URCDP Resolution 41/2021 provides model-clause guidance, and Resolution 23/2021 sets the country adequacy list (referencing Ibero-American standards and the EU GDPR) and addresses post-Schrems II US transfers. Decree 64/020 imposes a transfer impact assessment requirement for non-adequate destinations. URCDP Resolution 63/2023 extended recognised adequacy to South Korea and EU-US Data Privacy Framework-certified entities. No mandatory data-localisation regime was identified.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

Uruguay occupies a distinctive position among Latin American jurisdictions in the cross-border data transfer domain, holding a European Union adequacy recognition that places it among a very small number of jurisdictions in the region to have received that determination. This adequacy status means that personal-data transfers from EU-based controllers to Uruguay can proceed without the additional transfer-mechanism safeguards, such as standard contractual clauses or binding corporate rules, that would otherwise be required for transfers to jurisdictions lacking that determination. This is standing, durable context rather than a this-cycle development, but it is the frame within which this cycle's actual finding should be read.

That finding is URCDP Resolution No. 8/2026, issued 17 April 2026, in which Uruguay's data protection authority recommends the use of model or standard contractual clauses for international data transfers. The resolution is the most recent identified regulatory development within this module and within the jurisdiction's data protection framework more broadly this cycle. Its significance lies less in creating a new legal obligation, since it is framed as a recommendation, and more in signalling URCDP's active engagement with the mechanics of cross-border transfer governance at a moment when many jurisdictions globally are tightening their approach to international data flows. For a jurisdiction that already holds EU adequacy, promoting the use of model clauses reads most naturally as guidance oriented toward Uruguay's transfer relationships with jurisdictions that do not benefit from an equivalent adequacy arrangement, where Uruguayan controllers or processors sending data onward would otherwise lack a clear transfer-mechanism template.

The evidentiary basis for both the adequacy-status finding and the new resolution is secondary legal-commentary material (Recording Law and Allende & Brea respectively), rather than direct retrieval of the URCDP resolution text or the EU adequacy decision itself, though both are treated at Confirmed confidence given the specificity and consistency of dates and content across independent commentary sources. No primary URCDP or European Commission text was independently retrieved this cycle for either finding, which should be read as a sourcing note rather than a substantive doubt about either fact.

The module's overall trajectory this cycle is characterised as tightening, reflecting the introduction of new guidance activity within an otherwise stable and mature cross-border framework, rather than any weakening of Uruguay's transfer position or any threat to its underlying EU adequacy status, which remains unaffected by this development.

Outlook

The primary open question is whether URCDP's April 2026 model-clause recommendation remains guidance-level or is eventually formalised into a binding requirement for a defined category of cross-border transfers; the interpreter material available this cycle characterises it as a recommendation rather than a mandate, and no timeline for any further formalisation was identified. Given Uruguay's existing EU adequacy status, which is not itself under any identified review or reconsideration this cycle, the more consequential trajectory to watch is likely to be uptake of model clauses in Uruguay's data-transfer relationships with non-adequate jurisdictions, rather than any change to the EU relationship itself.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (8)
  1. ConfirmedOfficial Journal of the European Union — The European Commission adopted Implementing Decision 2012/484/EU on 21 August 2012, recognising Uruguay as ensuring an adequate level of protection for personal data transferred from the EU under Directive 95/46/EC.observed
  2. ConfirmedInternational Association of Privacy Professionals — Article 23 of Law 18.331 prohibits international transfers of personal data of any kind to countries or international organisations that do not provide adequate levels of protection.observed
  3. ConfirmedInternational Association of Privacy Professionals — The URCDP may authorise a transfer to a non-adequate country where the controller offers sufficient guarantees for the protection of individuals' fundamental rights, which may derive from appropriate contractual clauses.observed
  4. ConfirmedInternational Association of Privacy Professionals — URCDP Resolution No 41/2021 of 8 September 2021 provides guidance on the minimum recommended content of appropriate contractual clauses for international transfers of personal data to non-adequate countries.observed
  5. ConfirmedInternational Association of Privacy Professionals — URCDP Resolution No 23/2021 of 8 June 2021 established the list of countries considered adequate for international data transfers, based on the Ibero-American Data Protection Standards and the EU GDPR.observed
  6. ConfirmedInternational Association of Privacy Professionals — Following the invalidation of the EU-US Privacy Shield and the CJEU's Schrems II ruling, URCDP Resolution No 23/2021 requires that transfers to the United States be justified via data-subject consent or one of the Article 23 exceptions, with URCDP authorisation where applicable.observed
  7. ProbableInternational Association of Privacy Professionals — Article 6 of Decree No. 64/2020 requires controllers to carry out an impact assessment before transferring data to states or organisations lacking an adequate level of data protection.observed
  8. ConfirmedOneTrust DataGuidance — URCDP Resolution No 63/2023 of 21 November 2023 recognised South Korea and entities certified under the EU-US Data Privacy Framework as providing an adequate level of data protection for cross-border transfers.observed

#

This module carries no confirmed claims; all seven sub-modules are gaps requiring dedicated follow-up research against Uruguayan sectoral statutes.

Traffic-light rationale — Not assessedThis module carries no confirmed claims; all seven sub-modules are gaps requiring dedicated follow-up research against Uruguayan sectoral statutes.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed financial-sector DP overlay (e.g., banking-secrecy interaction with LPD) was located in this pass.

Absence provenance: unavailable. Searched: Uruguay secreto bancario protección de datos superposición, Uruguay Banco Central datos personales regulación.

Health Sector OverlayRed

No health-sector-specific data protection overlay was confirmed in this pass.

Absence provenance: unavailable. Searched: Uruguay datos de salud protección regulación sectorial.

Telecoms And EprivacyRed

No ePrivacy-equivalent telecoms/communications-specific regime was confirmed in this pass.

Absence provenance: unavailable. Searched: Uruguay ePrivacy telecomunicaciones datos regulación.

Employment DataRed

No employment-specific data protection code was confirmed in this pass.

Absence provenance: unavailable. Searched: Uruguay datos personales empleados regulación laboral.

Credit And ScoringRed

No verified Uruguay-specific credit-reporting/scoring statute text (equivalent to positive/negative solvency-file regimes elsewhere in the region) was confirmed in this pass.

Absence provenance: unavailable. Searched: Uruguay datos crediticios ley 17.838 registro deudores informes comerciales.

EducationRed

No education-sector-specific data protection rules were confirmed in this pass.

Absence provenance: unavailable. Searched: Uruguay protección datos educación estudiantes regulación.

InsuranceRed

No insurance-sector-specific data protection rules were confirmed in this pass.

Absence provenance: unavailable. Searched: Uruguay seguros datos personales regulación sectorial.

Category narrative50 words

No sector-specific overlays (banking secrecy, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) displacing or supplementing the general LPD regime were independently confirmed for Uruguay within this research pass. Uruguay is known to have separate banking-secrecy legislation and consumer-credit-reporting practices, but verified statutory citations tying these to data-protection-specific carve-outs were not retrieved.

#

No confirmed sub-module claims; this is a genuine regulatory gap or an under-researched area requiring dedicated follow-up.

Traffic-light rationale — Not assessedNo confirmed sub-module claims; this is a genuine regulatory gap or an under-researched area requiring dedicated follow-up.

Sub-modules (6)

Cookies And TrackersRed

No Uruguay-specific cookie/tracker consent instrument was confirmed.

Absence provenance: unavailable. Searched: Uruguay ley cookies rastreadores consentimiento web.

Dark PatternsRed

No dark-pattern prohibition specific to Uruguay's DP regime was confirmed.

Absence provenance: unavailable. Searched: Uruguay dark patterns prácticas engañosas datos.

Opt Out SignalsRed

No recognition of browser-level opt-out signals (e.g., GPC) was confirmed for Uruguay.

Absence provenance: unavailable. Searched: Uruguay Global Privacy Control señal de rechazo.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule specific to Uruguay was confirmed.

Absence provenance: unavailable. Searched: Uruguay clean room data collaboration datos personales.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising rule was confirmed for Uruguay.

Absence provenance: unavailable. Searched: Uruguay publicidad cross-context venta de datos regulación.

Direct MarketingAmber

General consent/purpose-limitation principles under the LPD would apply to direct marketing, but a dedicated direct-marketing consent/suppression regime was not confirmed.

Absence provenance: unavailable. Searched: Uruguay marketing directo datos personales consentimiento regulación.

Category narrative44 words

No dedicated cookie/tracker consent regime, dark-pattern prohibition, opt-out signal recognition, clean-room rule, cross-context-advertising rule, or direct-marketing-specific suppression regime was independently confirmed for Uruguay in this research pass. General LPD consent and purpose-limitation principles would apply to commercial/marketing processing, but no adtech-specific instrument was located.

#

One sub-module (state-surveillance carve-outs) is evidenced from primary-adjacent sources; the remaining five sub-modules are unconfirmed gaps.

Primary frameworkLaw No. 18.331 (LPD)
Traffic-light rationale — AmberOne sub-module (state-surveillance carve-outs) is evidenced from primary-adjacent sources; the remaining five sub-modules are unconfirmed gaps.

Sub-modules (6)

Profiling RestrictionsRed

No Art-22-GDPR-analogue profiling restriction was confirmed for Uruguay in this pass.

Absence provenance: unavailable. Searched: Uruguay perfilado decisiones automatizadas restricción ley.

Automated Decision Making TransparencyRed

No ADM-transparency/explanation right specific to Uruguay was confirmed.

Absence provenance: unavailable. Searched: Uruguay decisiones automatizadas transparencia derecho explicación.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime or general AI statute was confirmed for Uruguay.

Absence provenance: unavailable. Searched: Uruguay inteligencia artificial datos biométricos regulación 2025.

Biometric RegimeRed

No biometric-data-specific statute (facial recognition, fingerprint, gait) was confirmed for Uruguay in this pass.

Absence provenance: unavailable. Searched: Uruguay reconocimiento facial datos biométricos ley.

Genetic DataRed

No genetic-data-specific regime was confirmed for Uruguay in this pass.

Absence provenance: unavailable. Searched: Uruguay datos genéticos regulación protección.

State Surveillance CarveoutsAmber

Databases for public security, defence, or state-security purposes fall outside the LPD's general scope.

Claims (1):

  • Law 18.331 excludes from its scope databases whose purpose is public security, defence or state security, subject to any specific regulating law.
Category narrative48 words

The LPD carves databases serving public-security, defence or state-security purposes out of its general scope, which functions as a state-surveillance carve-out subject to any specific regulating law. No Uruguay-specific profiling restriction, ADM-transparency right, AI-specific risk-assessment regime, biometric-specific statute, or genetic-data-specific regime was independently confirmed in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ConfirmedInternational Association of Privacy Professionals — Law 18.331 excludes from its scope databases whose purpose is public security, defence or state security, subject to any specific regulating law.observed

#

No confirmed UY-specific claims for any of the five sub-modules; this is either a genuine regime gap or requires dedicated primary-text research against LPD articles on minors.

Traffic-light rationale — Not assessedNo confirmed UY-specific claims for any of the five sub-modules; this is either a genuine regime gap or requires dedicated primary-text research against LPD articles on minors.

Sub-modules (5)

Age VerificationRed

No Uruguay-specific age-verification requirement was confirmed.

Absence provenance: unavailable. Searched: Uruguay protección datos menores consentimiento edad ley 18.331.

Minor Profiling BansRed

No minor-specific profiling ban was confirmed for Uruguay.

Absence provenance: unavailable. Searched: Uruguay perfilado menores prohibición ley.

Education SettingsRed

No education-settings-specific children's-data rule was confirmed for Uruguay.

Absence provenance: unavailable. Searched: Uruguay datos personales estudiantes escuelas regulación.

Dependent AdultsRed

No dependent-adult (elderly, mentally incapacitated) data protection provision was confirmed for Uruguay.

Absence provenance: unavailable. Searched: Uruguay datos personales adultos dependientes incapacidad.

Category narrative53 words

No Uruguay-specific provisions on age of consent for data processing, parental-consent mechanisms, minor-profiling bans, education-settings-specific DP rules, or dependent-adult protections were independently confirmed in this research pass. Comparators from Spain (age 14 consent threshold under LOPDGDD) were located but are not applicable to the bound UY JID and are excluded per JID discipline.

#

Regulator powers and private right of action are well evidenced; enforcement-activity index, funding/capacity, collective redress and 180-day recent developments are unconfirmed gaps.

Primary frameworkLaw No. 18.331 (LPD) as implemented by Decree No. 64/020
Traffic-light rationale — AmberRegulator powers and private right of action are well evidenced; enforcement-activity index, funding/capacity, collective redress and 180-day recent developments are unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

URCDP may impose sanctions ranging from observations and warnings to database closure and fines for LPD non-compliance.

Claims (1):

  • Implementing decree provisions empower the URCDP to impose sanctions for non-compliance ranging from observations and warnings to closure of the database and the imposition of fines.

Enforcement Activity IndexAmber

URCDP has issued numerous guidance resolutions since 2017, but a quantified enforcement/fines activity index for the last 12 months was not located.

Claims (1):

  • The URCDP has issued a series of resolutions and guidance since 2017-2023 (de-identification guide, SCC guidance, adequacy resolutions) evidencing active regulatory/guidance output, though no comprehensive public enforcement-fine index was located in this research pass.

Regulator Funding And CapacityRed

No specific funding, budget or headcount figures for URCDP were confirmed in this pass.

Absence provenance: unavailable. Searched: URCDP presupuesto personal capacidad Uruguay.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to LPD enforcement was confirmed in this pass.

Absence provenance: unavailable. Searched: Uruguay acción de clase protección de datos personales.

Private Right Of ActionGreen

Data subjects may pursue a judicial Habeas Data action to enforce their rights directly, independent of URCDP administrative process.

Claims (1):

  • Data subjects may pursue a judicial Habeas Data action as a private right of action to enforce their data protection rights, in addition to filing complaints with the URCDP.

Recent Developments 180DRed

No Uruguay-specific data-protection legislative, case-law, guidance, or adequacy development within the last 180 days (February-August 2026) was confirmed in this research pass.

Absence provenance: unavailable. Searched: URCDP Uruguay 2025 2026 fine enforcement decision resolución, Uruguay data protection law 2026 URCDP adequacy GDPR.

Category narrative85 words

URCDP holds a graduated sanctioning power ranging from observations and warnings through database closure and fines, set out in implementing decree provisions. Data subjects retain a private right of action via the judicial Habeas Data proceeding in addition to URCDP complaints. URCDP has been an active guidance-issuing body (de-identification guide 2017, SCC guidance 2021, adequacy resolutions 2021/2023), though a quantified 12-month enforcement/fines activity index, regulator funding/headcount figures, a collective-redress/class-action mechanism, and confirmed developments within the last 180 days were not located in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy Professionals — Implementing decree provisions empower the URCDP to impose sanctions for non-compliance ranging from observations and warnings to closure of the database and the imposition of fines.observed
  2. ConfirmedInternational Association of Privacy Professionals — Data subjects may pursue a judicial Habeas Data action as a private right of action to enforce their data protection rights, in addition to filing complaints with the URCDP.observed
  3. UncertainOneTrust DataGuidance — The URCDP has issued a series of resolutions and guidance since 2017-2023 (de-identification guide, SCC guidance, adequacy resolutions) evidencing active regulatory/guidance output, though no comprehensive public enforcement-fine index was located in this research pass.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct23.53
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Uruguay
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 31 claim(s) (31 category placement(s)), 18 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redresscollective redress and class actions
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, cross_border_and_adequacy, and controller_processor_duties reached T1/T2 evidentiary density (EU Commission decision + multiple corroborating IAPP secondary reports on the 2018/2020 decree reforms) and were rated green/amber. lawful_processing_and_special_data and data_subject_rights and enforcement_and_redress reached T2/T3 partial coverage (amber) with confirmed core rights/DPO/sanctions findings but unconfirmed granular sub-modules (portability, lawful-bases enumeration, collective redress, funding/capacity, 180-day recent developments). algorithmic_biometric_and_surveillance_governance achieved one confirmed sub-module (state-surveillance carve-out) against five unconfirmed. sectoral_watch, adtech_and_commercial_privacy, and children_and_vulnerable_groups returned no Uruguay-specific T1-T3 findings in this pass and are carried as red/gap modules with explicit absent_field_provenance naming the searches run; these should not be read as 'no regime exists' but as 'not independently confirmed in this research pass' pending direct retrieval of LPD Spanish-language article text and any dedicated sectoral statutes (e.g., banking secrecy law, consumer credit reporting law).

Unresolved questions (10):

  • What is the precise enumerated catalogue of lawful bases under LPD Art. 5/6 and the specific consent-validity threshold text (equivalent to GDPR Art 7)?
  • Does Uruguay recognise a data-portability right, and if so under what statutory basis?
  • What are the exact statutory response-deadline windows for access/rectification/erasure requests?
  • Is there a dedicated ROPA (records of processing) obligation distinct from general accountability documentation duties?
  • Are there sector-specific overlays for banking secrecy, health data, telecoms/ePrivacy, employment, credit-scoring, education, or insurance that interact with the LPD?
  • Does Uruguay have any AI-specific regulation, biometric-specific statute, or genetic-data-specific regime?
  • What are Uruguay's specific age-of-consent and parental-consent rules for minors' data processing?
  • Is there a collective-redress or class-action mechanism available for LPD violations beyond individual Habeas Data actions?
  • What is URCDP's current funding, staffing, and quantified enforcement/fines activity over the last 12 months?
  • Have there been any Uruguay-specific data-protection legislative, judicial, or regulatory developments in the 180 days preceding 2026-08-05?

Escalate to primary-source review: yes